Show filters
496 Total Results
Displaying 301-310 of 496
Sort by:
Attacker Value
Unknown
CVE-2020-1895
Disclosure Date: April 09, 2020 (last updated February 21, 2025)
A large heap overflow could occur in Instagram for Android when attempting to upload an image with specially crafted dimensions. This affects versions prior to 128.0.0.26.128.
0
Attacker Value
Unknown
CVE-2019-10180
Disclosure Date: March 31, 2020 (last updated February 21, 2025)
A vulnerability was found in all pki-core 10.x.x version, where the Token Processing Service (TPS) did not properly sanitize several parameters stored for the tokens, possibly resulting in a Stored Cross Site Scripting (XSS) vulnerability. An attacker able to modify the parameters of any token could use this flaw to trick an authenticated user into executing arbitrary JavaScript code.
0
Attacker Value
Unknown
CVE-2019-10179
Disclosure Date: March 20, 2020 (last updated February 21, 2025)
A vulnerability was found in all pki-core 10.x.x versions, where the Key Recovery Authority (KRA) Agent Service did not properly sanitize recovery request search page, enabling a Reflected Cross Site Scripting (XSS) vulnerability. An attacker could trick an authenticated victim into executing specially crafted Javascript code.
0
Attacker Value
Unknown
CVE-2019-10221
Disclosure Date: March 20, 2020 (last updated February 21, 2025)
A Reflected Cross Site Scripting vulnerability was found in all pki-core 10.x.x versions, where the pki-ca module from the pki-core server. This flaw is caused by missing sanitization of the GET URL parameters. An attacker could abuse this flaw to trick an authenticated user into clicking a specially crafted link which can execute arbitrary code when viewed in a browser.
0
Attacker Value
Unknown
CVE-2020-1696
Disclosure Date: March 20, 2020 (last updated February 21, 2025)
A flaw was found in the all pki-core 10.x.x versions, where Token Processing Service (TPS) where it did not properly sanitize Profile IDs, enabling a Stored Cross-Site Scripting (XSS) vulnerability when the profile ID is printed. An attacker with sufficient permissions could trick an authenticated victim into executing a specially crafted Javascript code.
0
Attacker Value
Unknown
CVE-2019-10178
Disclosure Date: March 18, 2020 (last updated February 21, 2025)
It was found that the Token Processing Service (TPS) did not properly sanitize the Token IDs from the "Activity" page, enabling a Stored Cross Site Scripting (XSS) vulnerability. An unauthenticated attacker could trick an authenticated victim into creating a specially crafted activity, which would execute arbitrary JavaScript code when viewed in a browser. All versions of pki-core are believed to be vulnerable.
0
Attacker Value
Unknown
CVE-2019-10146
Disclosure Date: March 18, 2020 (last updated February 21, 2025)
A Reflected Cross Site Scripting flaw was found in all pki-core 10.x.x versions module from the pki-core server due to the CA Agent Service not properly sanitizing the certificate request page. An attacker could inject a specially crafted value that will be executed on the victim's browser.
0
Attacker Value
Unknown
CVE-2019-18917
Disclosure Date: March 16, 2020 (last updated February 21, 2025)
A potential security vulnerability has been identified for certain HP Printers and All-in-Ones that would allow bypassing account lockout.
0
Attacker Value
Unknown
CVE-2020-7959
Disclosure Date: February 17, 2020 (last updated February 21, 2025)
LabVantage LIMS 8.3 does not properly maintain the confidentiality of database names. For example, the web application exposes the database name. An attacker might be able to enumerate database names by providing his own database name in a request, because the response will return an 'Unrecognized Database exception message if the database does not exist.
0
Attacker Value
Unknown
CVE-2020-9025
Disclosure Date: February 17, 2020 (last updated February 21, 2025)
Iteris Vantage Velocity Field Unit 2.4.2 devices have multiple stored XSS issues in all parameters of the Start Data Viewer feature of the /cgi-bin/loaddata.py script.
0